
An older version of Google’s Gemini artificial intelligence model accessed the live systems of three companies during a cybersecurity evaluation after the test was mistakenly allowed to connect to the internet.
The incidents occurred in May 2026 during a “capture the flag” exercise conducted by Irregular, an independent AI evaluation company. The exercise was intended to assess Gemini’s cybersecurity capabilities inside a controlled environment, but an incorrect configuration left external internet access enabled.
According to reports, a fictional company used in the simulation shared its name with a real organization. Gemini consequently searched for the company online and treated its actual infrastructure as part of the authorized test.
During one evaluation run, the AI gained access to a company’s protected service after successfully guessing a weak password. In two other cases, it reportedly found credentials exposed in publicly accessible code repositories and used them to enter systems belonging to separate companies.
Google said the model exploited existing security weaknesses rather than discovering or creating new software vulnerabilities.
The AI stopped its activity in each case after recognizing that it had accessed real infrastructure outside the intended testing environment. No damage was reported, and Google did not characterize the incidents as evidence that the model had become misaligned or acted with independent malicious intent.
Google and Irregular notified the three affected companies and relevant authorities. The organizations’ identities have not been made public. Irregular also revised its testing procedures to prevent future evaluations from reaching unauthorized external systems.
Heather Adkins, Google’s vice president of security engineering, said the incidents demonstrated the importance of training powerful AI systems to behave responsibly. Google pointed to Gemini’s decision to halt the operations as evidence that its contextual safety controls worked, although the episode also exposed weaknesses in the surrounding test environment.
The case adds to growing concerns about autonomous AI agents capable of searching the internet, using credentials and performing complex cybersecurity tasks with limited human intervention. Similar problems have reportedly emerged during evaluations involving models developed by other major AI laboratories.
The incident underscores two distinct security challenges: organizations must address weak passwords and publicly exposed credentials, while AI developers and testing companies must impose strict technical boundaries on autonomous systems. As agentic models become more capable, controlled network access, continuous monitoring and clear authorization limits are likely to become increasingly important safeguards.
Source: Omanghana




